Skip to content

captain-hook: 馃悰 Fail open when hook transcript evidence is missing - #196

Merged
yasyf merged 1 commit into
mainfrom
fix/missing-evidence-failopen
Sep 26, 2026
Merged

yasyf merged 1 commit into
mainfrom
fix/missing-evidence-failopen

Conversation

@yasyf

@yasyf yasyf commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Context

A UserPromptSubmit hook that reads transcript evidence prints a Python traceback and exits 1 when its transcript path is absent. The snapshot service returns the typed missing status, but the hook boundary does not include that status in its fail-open set.

Summary

Treat missing transcript evidence as incomplete at the hook boundary. Keep invalid requests, parse errors, and permission failures visible. Add a focused UserPromptSubmit regression for both an available and an absent transcript.

Motivation

A missing transcript cannot support a hook decision and should not interrupt a prompt with a stack trace.

Details

The error was reproduced against the signed 12.59.5 host with a synthetic UserPromptSubmit hook. The absent path returned EvidenceIncomplete("missing") and a traceback; the available path completed normally. ruff check and git diff --check pass. The full test matrix runs in CI.

@yasyf
yasyf force-pushed the fix/missing-evidence-failopen branch 2 times, most recently from dcdbc6d to 9da97c1 Compare September 26, 2026 07:33
Context: UserPromptSubmit prints a Python traceback when its transcript path is absent.

Summary: Treat typed missing snapshot evidence as incomplete at the hook boundary and cover valid and missing prompt paths.

Motivation: A missing transcript cannot support a hook decision and should not interrupt a prompt.

Details: Preserve visible invalid-request and permission errors, document the fix, and return an empty allow response for missing evidence.
@yasyf
yasyf force-pushed the fix/missing-evidence-failopen branch from 9da97c1 to 45fdf9c Compare September 26, 2026 07:34
@yasyf
yasyf marked this pull request as ready for review September 26, 2026 07:37
@yasyf
yasyf merged commit 166c4da into main Sep 26, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant